Re: [SECURITY] [DSA 2337-1] xen security update

2011-11-22 Thread Davy Gigan
graded, uses the same policy as the linux kernel and says the machine needs to be rebooted (using /var/lib/reboot-required) ? This would prevent users to upgrade and forget about the reboot, thinking they are protected from the issue. Regards -- Davy Gigan Administrateur Systèmes et Rése

Re: secure file transfer

2002-06-04 Thread Davy Gigan
System server), you can find testing packages and the home page is at http://www.fs.net. With this kind of system, you'll be able to allow someone to mount his homedir but nothing else. -- Davy Gigan System & Network Administration [Please no HTML, I'm not a browser] University

Re: secure file transfer

2002-06-04 Thread Davy Gigan
System server), you can find testing packages and the home page is at http://www.fs.net. With this kind of system, you'll be able to allow someone to mount his homedir but nothing else. -- Davy Gigan System & Network Administration [Please no HTML, I'm not a browser] University

Re: logging iptables

2002-04-22 Thread Davy Gigan
information into its own log file in /var/log > ? You can try syslog-ng with filters redirecting your firewall loggin in whatever file you want. Regards. -- Davy Gigan System & Network Administration [Please no HTML, I'm not a browser] University Of Caen (France) [Pas d

Re: logging iptables

2002-04-22 Thread Davy Gigan
information into its own log file in /var/log > ? You can try syslog-ng with filters redirecting your firewall loggin in whatever file you want. Regards. -- Davy Gigan System & Network Administration [Please no HTML, I'm not a browser] University Of Caen (France) [Pas d

Re: best way to create pop only accounts

2002-03-11 Thread Davy Gigan
Pedro Zorzenon Neto writes: > Hi, > >Which is the best way to create a POP only account? just change the > last field in /etc/passwd to /bin/false? What about using qmail with vpopmail ? Simple, efficient, and really disconnected from the underlying server ... -- Davy

Re: best way to create pop only accounts

2002-03-11 Thread Davy Gigan
Pedro Zorzenon Neto writes: > Hi, > >Which is the best way to create a POP only account? just change the > last field in /etc/passwd to /bin/false? What about using qmail with vpopmail ? Simple, efficient, and really disconnected from the underlying server ... -- Davy

Re: ssh ip address

2002-02-19 Thread Davy Gigan
Eduardo J. Gargiulo writes: > but I need the IP address i'm connecting from in the shell script and > the address is assigned dynamically. echo $SSH_CLIENT, you'll get ip, remote port and local port. -- Davy Gigan System & Network Administration [Please no HTM

Re: ssh ip address

2002-02-19 Thread Davy Gigan
Eduardo J. Gargiulo writes: > but I need the IP address i'm connecting from in the shell script and > the address is assigned dynamically. echo $SSH_CLIENT, you'll get ip, remote port and local port. -- Davy Gigan System & Network Administration [Please no HTM

Re: Makejail

2002-02-19 Thread Davy Gigan
#x27;ve created before in about 30 minutes, it sounds good. Regards PS: i know syslog-ng has a chroot option, but i like to have all the stuff in a separated place. -- Davy Gigan System & Network Administration [Please no HTML, I'm not a browser] University Of Caen (France) [Pas d'HTML, je ne suis pas un navigateur]

Re: Makejail

2002-02-19 Thread Davy Gigan
#x27;ve created before in about 30 minutes, it sounds good. Regards PS: i know syslog-ng has a chroot option, but i like to have all the stuff in a separated place. -- Davy Gigan System & Network Administration [Please no HTML, I'm not a browser] University Of Caen (France)

Re: MySQL<->Firewall

2002-01-08 Thread Davy Gigan
ver with apache/php is the only one to use mysql, you don't need tcp, unix socket will be sufficient. Regards. -- Davy Gigan System & Network Administration [Please no HTML, I'm not a browser] University Of Caen (France) [Pas d'HTML, je ne suis pas un navigateur]

Re: MySQL<->Firewall

2002-01-08 Thread Davy Gigan
ver with apache/php is the only one to use mysql, you don't need tcp, unix socket will be sufficient. Regards. -- Davy Gigan System & Network Administration [Please no HTML, I'm not a browser] University Of Caen (France) [Pas d'HTML, je ne suis pas un navigate

Re: log iptables

2001-11-08 Thread Davy Gigan
would understand it. -- Davy Gigan System & Network Administration University Of Caen (France)

Re: log iptables

2001-11-08 Thread Davy Gigan
would understand it. -- Davy Gigan System & Network Administration University Of Caen (France) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Sniffing SSH and HTTPS

2001-08-28 Thread Davy Gigan
s of ssl when used in https (or use of 'magic' ?) ... -- Davy Gigan System & Network Administration University Of Caen (France)

Re: Sniffing SSH and HTTPS

2001-08-28 Thread Davy Gigan
Jan-Hendrik Palic writes: > >Don't know for https, but that's not a surprise then. > > Why? Because of the sentence below : 'Remember there is no 100% secure software.' ;-) -- Davy Gigan System & Network Administration University Of Caen (France)

Re: Sniffing SSH and HTTPS

2001-08-28 Thread Davy Gigan
OpenSSH_2.9p2 or OpenSSH_2.5.2p2 (which is last in debian security's updates) ... for the moment. Remember there is no 100% secure software. Don't know for https, but that's not a surprise then. -- Davy Gigan System & Network Administration University Of Caen (France)

Re: Sniffing SSH and HTTPS

2001-08-28 Thread Davy Gigan
s of ssl when used in https (or use of 'magic' ?) ... -- Davy Gigan System & Network Administration University Of Caen (France) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Sniffing SSH and HTTPS

2001-08-28 Thread Davy Gigan
Jan-Hendrik Palic writes: > >Don't know for https, but that's not a surprise then. > > Why? Because of the sentence below : 'Remember there is no 100% secure software.' ;-) -- Davy Gigan System & Network Administration University Of Caen (France)

Re: Sniffing SSH and HTTPS

2001-08-28 Thread Davy Gigan
OpenSSH_2.9p2 or OpenSSH_2.5.2p2 (which is last in debian security's updates) ... for the moment. Remember there is no 100% secure software. Don't know for https, but that's not a surprise then. -- Davy Gigan System & Network Administration University Of Caen (France) -- To UNSUBSCRIB

Re: inetd questions

2001-07-31 Thread Davy Gigan
ns. netstat -ap (as root) gives you access to the pid of processus that uses ports on your machine, even listening or not (-a). Ports referenced as 'unknown' are generally due to services depending on a portmapper. You're probably using this machine as nis(+), nfs (or something

Re: inetd questions

2001-07-31 Thread Davy Gigan
ns. netstat -ap (as root) gives you access to the pid of processus that uses ports on your machine, even listening or not (-a). Ports referenced as 'unknown' are generally due to services depending on a portmapper. You're probably using this machine as nis(+), nfs (or something

Re: ipchains

2001-06-30 Thread Davy Gigan
listen for connection. Are you sure your web browser configuration under win2k does not use an http proxy ? In this case, proxy machine access is not yet modified by your rules and can access your machine via web. -- Davy Gigan System & Network Administration University Of Caen (France)

Re: ipchains

2001-06-30 Thread Davy Gigan
listen for connection. Are you sure your web browser configuration under win2k does not use an http proxy ? In this case, proxy machine access is not yet modified by your rules and can access your machine via web. -- Davy Gigan System & Network Administration University Of Caen (France)

Re: Re[2]: Wierd file name?

2001-06-30 Thread Davy Gigan
ot;[" as a program that checks this epression. Exactly : Try to execute a csh script without this command present in your path, it won't work very well ;-) Maybye it should be a symbolic link to /usr/bin/test ? #!/bin/csh [ -d /bin ] && echo cool ; -- Davy Gigan System & Network Administration University Of Caen (France)

Re: Re[2]: Wierd file name?

2001-06-30 Thread Davy Gigan
ot;[" as a program that checks this epression. Exactly : Try to execute a csh script without this command present in your path, it won't work very well ;-) Maybye it should be a symbolic link to /usr/bin/test ? #!/bin/csh [ -d /bin ] && echo cool ; -- Davy Gigan Syste

Re: How to route

2001-06-28 Thread Davy Gigan
> And why I need bridging...? because I don't want to modify the router as > my old good poor manager asked to me...! As someaone already said : it's another level of security to modify your router. Bye. -- Davy Gigan System & Network Administration University Of Caen (France)

Re: How to route

2001-06-28 Thread Davy Gigan
eed bridging...? because I don't want to modify the router as > my old good poor manager asked to me...! As someaone already said : it's another level of security to modify your router. Bye. -- Davy Gigan System & Network Administration University Of Caen (France) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: How to route

2001-06-26 Thread Davy Gigan
are significantly different ... You should take a look to kernel docs and read a little about bridging (i think you don't need it, but i may be wrong, may i missed something) ... Now it's time to compile ... Information about those things are outside the scope of this list i suppose. Regards. -- Davy Gigan System & Network Administration University Of Caen (France)

Re: How to route

2001-06-26 Thread Davy Gigan
are significantly different ... You should take a look to kernel docs and read a little about bridging (i think you don't need it, but i may be wrong, may i missed something) ... Now it's time to compile ... Information about those things are outside the scope of this list i suppose.

Re: How to route

2001-06-25 Thread Davy Gigan
a nat for servers address, you can do it with ipchains / iptables. see nat and port forwarding howtos for a complete explaination ... > > > What do you suggest? As a conclusion, you'll ask your manager to modify router's configuration anyway. > Thanks!, Marco Regards. -- Davy Gigan System & Network Administration University Of Caen (France)

Re: How to route

2001-06-25 Thread Davy Gigan
or servers address, you can do it with ipchains / iptables. see nat and port forwarding howtos for a complete explaination ... > > > What do you suggest? As a conclusion, you'll ask your manager to modify router's configuration anyway. > Thanks!, Marco Regards. -- Davy Gigan System & Network Administration University Of Caen (France) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]